Paragon and Italy: when the spyware vendor terminates the state contract
5 min read
A year ago, on 31 January 2025, around ninety people in more than twenty countries received a WhatsApp notification: their phone had been targeted by Graphite, the spyware made by Paragon Solutions, the Israeli company that presents itself as the sector’s “ethical” vendor — selling only to democracies, under a binding usage framework. The list included Fanpage.it editor Francesco Cancellato and activists from the NGO Mediterranea Saving Humans. A few days later, the first concrete consequence came neither from a court nor from Parliament: it came from the vendor, which terminated its contract with Italy. Twelve months on, it is worth asking what has changed. Short answer: a great deal in terms of transparency, almost nothing in terms of the rules.
The facts, in order
- 31 January 2025: WhatsApp notifies around ninety users — many of them journalists and civil-society figures — that they had been targeted by Graphite through a zero-click attack: a malicious PDF delivered inside WhatsApp groups, requiring no click at all. Meta sends Paragon a cease-and-desist letter. Among the Italians notified: Cancellato, then Luca Casarini and Giuseppe Caccia of Mediterranea.
- Early February 2025: The Guardian reveals that Paragon has terminated its contract with Italy, deeming its terms of service and its own “ethical framework” to have been breached. The government rules out any involvement of the intelligence services in spying on the journalists.
- 12 February 2025: the government confirms in Parliament that Italy was a Paragon client and that the intelligence services used Graphite “on several occasions”, always — it maintains — within the bounds of the law.
- 5 June 2025: the declassified COPASIR report (Italy’s parliamentary committee for intelligence oversight) confirms that AISE and AISI — Italy’s foreign and domestic intelligence agencies — employed Graphite. Casarini and Caccia were placed under authorised surveillance as part of action against irregular immigration, activity the Committee judges lawful. On the Cancellato case the conclusion is unambiguous: the Italian services did not spy on him. Who did remains unanswered.
- 9 June 2025: Paragon states that it offered the government and COPASIR a way to technically verify the attack on Cancellato, and that it terminated the contracts after this offer was refused. The institutions counter that the verification would have exposed confidential methods; the two accounts even diverge on who ended the contract first.
- 12 June 2025: Citizen Lab publishes the first forensic confirmation of Graphite on iPhone: among the victims is Ciro Pellegrino, head of Fanpage’s Naples desk, who received an Apple notification on 29 April.
- The public prosecutors’ offices in Rome and Naples have opened investigations, still ongoing.
The one-year assessment is asymmetric. Transparency has changed: a European government has admitted to using commercial spyware, and a parliamentary body has declassified a report on the matter. Almost nothing else has changed: it is still not known who attacked the editor of a national news outlet, no new rules on the State’s use of such tools have emerged, and Graphite remains on the market.
Lesson 1: “ethical” is the vendor’s adjective, not a guarantee for the buyer
The paradox of this case is that the only safeguard that actually kicked in was a private one: not a judge, not an authority — the vendor. Paragon applied its own clauses and cut off a sovereign client. Whether or not one believes its account, the pattern is instructive for anyone adopting powerful technology: if the usage rules are written and enforced solely by the vendor, governance sits outside your organisation. And it cuts both ways: the vendor that certifies you “ethical” today can, for reasons of its own, terminate tomorrow a tool you depend on. Usage policies — who can do what, to whom, under what authorisation — are written in-house and verified, before the contract is signed.
Lesson 2: human oversight is proven by records, not by statements
COPASIR was able to reconstruct only what had been authorised and logged: decrees, dates, the targets of the services’ operations. Everything else — starting with the attack on Cancellato — remained beyond the reach of any verification. This is the difference between a governed tool and one that is merely used: an explicit chain of authorisation, auditable usage records, a named individual accountable for every deployment. The same holds for state spyware as for an AI system inside a public-sector body: when the question “who authorised this?” arrives, the answer must sit in a log, not in a press release.
Lesson 3: sovereignty is the capacity to verify
When it came to establishing the facts, Italy found itself facing an uncomfortable choice: accept the audit offered by the foreign vendor, exposing confidential methods, or forgo the technical truth. The prosecutors, meanwhile, depend on the cooperation of a company outside their jurisdiction. This is the operational definition of dependency: if the tool is a closed box belonging to another jurisdiction, verification is a concession, not a right. For critical technologies — whether for surveillance or for decision-making — there is one question to ask before purchase: are data, logs and operation inspectable by those who use them, without having to ask permission? Compliance that holds up starts there.
What to do if you adopt technologies with high abuse potential
- Write your own usage policies, stricter than the vendor’s: scope, lawful targets, explicit exclusions.
- Formalise the chain of authorisation: every use has a requester, an approver, and a tamper-proof record.
- Negotiate reciprocal audit rights: you must be able to verify the tool; the vendor must not be able to reconstruct your usage beyond what is necessary.
- Prepare an exit plan: what happens to operations and data if the contract collapses — including at the vendor’s own initiative.
Do you need to adopt powerful tools without ceding control over them? Half an hour with one of our experts for an initial map of risks and clauses.
Sources
- TechCrunch — Spyware maker Paragon terminates contract with Italian government (6 February 2025)
- TechCrunch — Italian lawmakers say Italy used spyware against immigration activists, but not against journalist (6 June 2025)
- The Citizen Lab — Graphite Caught: first forensic confirmation of Paragon’s iOS spyware (12 June 2025)